Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Hard
A security auditor is investigating a potential privilege escalation path in an Azure subscription using Prisma Cloud CIEM. They have identified a service principal with 'Contributor' access to a resource group, and within that resource group, there's a custom role definition that includes 'Microsoft.Authorization/roleDefinitions/write' permission. What CIEM analysis capability would most effectively highlight this specific type of risk?
- AIAM Visibility Dashboard
- BIdentity Exposure Analysis
- CIdentity Graph Analysis
- DInactive Identity Remediation
Show answer & explanationAnswer & explanation
Correct answer: C. Identity Graph Analysis
Identity Graph Analysis visualizes and analyzes the relationships between identities, resources, and permissions, including transitive trusts and potential escalation paths, which is essential for uncovering complex risks like custom role definition manipulation.
Why the other options are wrong
- A. The dashboard provides an overview, but won't specifically map out complex escalation paths.
- B. Identity exposure analysis focuses on publicly exposed identities or easily exploitable misconfigurations, not complex privilege chains.
- D. Inactive identity remediation deals with unused identities, not active privilege escalation paths.
Identity Graph Analysis
A CIEM capability that maps and visualizes all relationships between identities, resources, and permissions within a cloud environment, revealing complex access paths and potential privilege escalation vectors.
- Identifies direct and transitive access paths.
- Helps uncover hidden privilege escalation opportunities.
- Crucial for understanding complex IAM landscapes in multi-cloud.
Memory trick: Identity Graph Analysis is like a detective's corkboard, connecting all the suspects (identities) and their actions (permissions) to the crime scene (resources).